StackRadar

CVE-2026-59889

Medium

Advisory

Published 21 Jul 2026In the index since 5 Sept 2026
Severity
Medium
worst across findings
CVSS
6.5
base score, highest
EPSS
0.003
28th percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
224
of 17,781 indexed, latest versions
Container images
224
deployed by those charts
Fix available
1 of 1
affected package

jackson-databind: @JsonView bypassed for @JsonUnwrapped container properties on deserialization

Carried by container images the latest versions of 224 of 17,781 indexed charts deploy, on 224 images.

Affected packageAffected versionsFixed inImages
jackson-databindmaven2.18.0, 2.18.1, 2.18.2, 2.18.3+17 more2.18.9, 2.21.5, 2.22.1, 3.1.5+1 more224
OSV records
GHSA-5gvw-p9qm-jgwh

Charts affected

224 by stars
ChartLatestAffected imagesRadar Score
fineractfineract-openshift0.1.11 of 4See more

fineract fineract-openshift 0.1.1

1 of the 4 container images this version deploys carry CVE-2026-59889.

Container imageDigestPackageFixed in
apache/fineract:1.12.1a83cf1980609
jackson-databind@2.18.3
2.18.9

Open the chart page →

7,792
flyteconnectorflyte2.0.01 of 1See more

flyteconnector flyte 2.0.0

1 of the 1 container images this version deploys carry CVE-2026-59889.

Container imageDigestPackageFixed in
ghcr.io/flyteorg/flyte-connectors:py3.12-v2.3.6896fc7b18b1b
jackson-databind@2.21.2
2.21.5

Open the chart page →

3,463
edge-caiasoftfolio-org0.1.321 of 1See more

edge-caiasoft folio-org 0.1.32

1 of the 1 container images this version deploys carry CVE-2026-59889.

Container imageDigestPackageFixed in
folioci/edge-caiasoft:latestc3cfa89eee2f
jackson-databind@2.21.4
2.21.5

Open the chart page →

525
edge-connexionfolio-org0.1.51 of 1See more

edge-connexion folio-org 0.1.5

1 of the 1 container images this version deploys carry CVE-2026-59889.

Container imageDigestPackageFixed in
folioci/edge-connexion:latestb4863d135524
jackson-databind@2.18.2
2.18.9

Open the chart page →

1,132
edge-dematicfolio-org0.1.331 of 1See more

edge-dematic folio-org 0.1.33

1 of the 1 container images this version deploys carry CVE-2026-59889.

Container imageDigestPackageFixed in
folioci/edge-dematic:latest48c9b1d180d4
jackson-databind@3.1.4
3.1.5

Open the chart page →

525
edge-inn-reachfolio-org0.1.41 of 1See more

edge-inn-reach folio-org 0.1.4

1 of the 1 container images this version deploys carry CVE-2026-59889.

Container imageDigestPackageFixed in
folioci/edge-inn-reach:latestc64e4d9dd3fc
jackson-databind@3.1.4
3.1.5

Open the chart page →

525
edge-ncipfolio-org0.1.281 of 1See more

edge-ncip folio-org 0.1.28

1 of the 1 container images this version deploys carry CVE-2026-59889.

Container imageDigestPackageFixed in
folioci/edge-ncip:lateste760dbb81d1a
jackson-databind@2.18.2
2.18.9

Open the chart page →

820
edge-oai-pmhfolio-org0.1.311 of 1See more

edge-oai-pmh folio-org 0.1.31

1 of the 1 container images this version deploys carry CVE-2026-59889.

Container imageDigestPackageFixed in
folioci/edge-oai-pmh:latesteedfcbc29792
jackson-databind@2.18.2
2.18.9

Open the chart page →

874
edge-ordersfolio-org0.1.301 of 1See more

edge-orders folio-org 0.1.30

1 of the 1 container images this version deploys carry CVE-2026-59889.

Container imageDigestPackageFixed in
folioci/edge-orders:latest1ef654ee9f23
jackson-databind@2.18.6
2.18.9

Open the chart page →

735
edge-patronfolio-org0.1.281 of 1See more

edge-patron folio-org 0.1.28

1 of the 1 container images this version deploys carry CVE-2026-59889.

Container imageDigestPackageFixed in
folioci/edge-patron:latest682b852e056d
jackson-databind@3.1.0
3.1.5

Open the chart page →

905
edge-rtacfolio-org0.1.281 of 1See more

edge-rtac folio-org 0.1.28

1 of the 1 container images this version deploys carry CVE-2026-59889.

Container imageDigestPackageFixed in
folioci/edge-rtac:latest15ef73b1abd0
jackson-databind@3.0.4
3.1.5

Open the chart page →

1,259
edge-sip2folio-org0.1.281 of 1See more

edge-sip2 folio-org 0.1.28

1 of the 1 container images this version deploys carry CVE-2026-59889.

Container imageDigestPackageFixed in
folioci/edge-sip2:latest86106f20ef51
jackson-databind@2.21.4
2.21.5

Open the chart page →

253
mod-agreementsfolio-org0.1.321 of 1See more

mod-agreements folio-org 0.1.32

1 of the 1 container images this version deploys carry CVE-2026-59889.

Container imageDigestPackageFixed in
folioci/mod-agreements:latest29c3f233a498
jackson-databind@2.22.0
2.22.1

Open the chart page →

1,874
mod-auditfolio-org0.1.361 of 1See more

mod-audit folio-org 0.1.36

1 of the 1 container images this version deploys carry CVE-2026-59889.

Container imageDigestPackageFixed in
folioci/mod-audit:latest88f40730ed45
jackson-databind@3.1.4
3.1.5

Open the chart page →

267
mod-calendarfolio-org0.1.341 of 1See more

mod-calendar folio-org 0.1.34

1 of the 1 container images this version deploys carry CVE-2026-59889.

Container imageDigestPackageFixed in
folioci/mod-calendar:latest22f65982efd7
jackson-databind@3.1.4
3.1.5

Open the chart page →

415
mod-circulationfolio-org0.1.351 of 1See more

mod-circulation folio-org 0.1.35

1 of the 1 container images this version deploys carry CVE-2026-59889.

Container imageDigestPackageFixed in
folioci/mod-circulation:latest3eecd2ac2d8a
jackson-databind@2.18.6
2.18.9

Open the chart page →

497
mod-circulation-storagefolio-org0.1.351 of 1See more

mod-circulation-storage folio-org 0.1.35

1 of the 1 container images this version deploys carry CVE-2026-59889.

Container imageDigestPackageFixed in
folioci/mod-circulation-storage:latest6bdddcafbc0f
jackson-databind@2.18.6
2.18.9

Open the chart page →

658
mod-configurationfolio-org0.1.341 of 1See more

mod-configuration folio-org 0.1.34

1 of the 1 container images this version deploys carry CVE-2026-59889.

Container imageDigestPackageFixed in
folioci/mod-configuration:latestdd0cdc89670a
jackson-databind@2.18.6
2.18.9

Open the chart page →

711
mod-copycatfolio-org0.1.31 of 1See more

mod-copycat folio-org 0.1.3

1 of the 1 container images this version deploys carry CVE-2026-59889.

Container imageDigestPackageFixed in
folioci/mod-copycat:latest1513fad2b799
jackson-databind@2.18.6
2.18.9

Open the chart page →

1,466
mod-coursesfolio-org0.1.341 of 1See more

mod-courses folio-org 0.1.34

1 of the 1 container images this version deploys carry CVE-2026-59889.

Container imageDigestPackageFixed in
folioci/mod-courses:latest68ca414f5596
jackson-databind@2.18.2
2.18.9

Open the chart page →

1,533
mod-data-exportfolio-org0.1.401 of 1See more

mod-data-export folio-org 0.1.40

1 of the 1 container images this version deploys carry CVE-2026-59889.

Container imageDigestPackageFixed in
folioci/mod-data-export:latest0cc86bf09755
jackson-databind@3.0.4
3.1.5

Open the chart page →

1,393
mod-data-export-springfolio-org0.1.41 of 1See more

mod-data-export-spring folio-org 0.1.4

1 of the 1 container images this version deploys carry CVE-2026-59889.

Container imageDigestPackageFixed in
folioci/mod-data-export-spring:latestf1d7caf4544b
jackson-databind@3.0.4
3.1.5

Open the chart page →

1,253
mod-data-export-workerfolio-org0.1.151 of 1See more

mod-data-export-worker folio-org 0.1.15

1 of the 1 container images this version deploys carry CVE-2026-59889.

Container imageDigestPackageFixed in
folioci/mod-data-export-worker:latest1ad1811c9b37
jackson-databind@3.0.4
3.1.5

Open the chart page →

1,214
mod-ebsconetfolio-org0.1.31 of 1See more

mod-ebsconet folio-org 0.1.3

1 of the 1 container images this version deploys carry CVE-2026-59889.

Container imageDigestPackageFixed in
folioci/mod-ebsconet:latest3ae8cb99daa3
jackson-databind@3.1.0
3.1.5

Open the chart page →

1,203
mod-emailfolio-org0.1.341 of 1See more

mod-email folio-org 0.1.34

1 of the 1 container images this version deploys carry CVE-2026-59889.

Container imageDigestPackageFixed in
folioci/mod-email:latest79ea8e2e7ebf
jackson-databind@2.18.2
2.18.9

Open the chart page →

866
mod-erm-usage-harvesterfolio-org0.1.341 of 1See more

mod-erm-usage-harvester folio-org 0.1.34

1 of the 1 container images this version deploys carry CVE-2026-59889.

Container imageDigestPackageFixed in
folioci/mod-erm-usage-harvester:latest2d6767933c59
jackson-databind@2.18.6
2.18.9

Open the chart page →

563
mod-event-configfolio-org0.1.341 of 1See more

mod-event-config folio-org 0.1.34

1 of the 1 container images this version deploys carry CVE-2026-59889.

Container imageDigestPackageFixed in
folioci/mod-event-config:latest0192adad3897
jackson-databind@3.1.4
3.1.5

Open the chart page →

420
mod-feesfinesfolio-org0.1.341 of 1See more

mod-feesfines folio-org 0.1.34

1 of the 1 container images this version deploys carry CVE-2026-59889.

Container imageDigestPackageFixed in
folioci/mod-feesfines:latestfe3a7049f2fb
jackson-databind@2.18.2
2.18.9

Open the chart page →

663
mod-financefolio-org0.1.341 of 1See more

mod-finance folio-org 0.1.34

1 of the 1 container images this version deploys carry CVE-2026-59889.

Container imageDigestPackageFixed in
folioci/mod-finance:latest14450bc15430
jackson-databind@2.21.4
2.21.5

Open the chart page →

534
mod-finance-storagefolio-org0.1.341 of 1See more

mod-finance-storage folio-org 0.1.34

1 of the 1 container images this version deploys carry CVE-2026-59889.

Container imageDigestPackageFixed in
folioci/mod-finance-storage:latest4bc4057abaea
jackson-databind@3.1.4
3.1.5

Open the chart page →

413
mod-inn-reachfolio-org0.1.71 of 1See more

mod-inn-reach folio-org 0.1.7

1 of the 1 container images this version deploys carry CVE-2026-59889.

Container imageDigestPackageFixed in
folioci/mod-inn-reach:latestcc8584e43382
jackson-databind@3.1.4
3.1.5

Open the chart page →

512
mod-inventory-updatefolio-org0.1.21 of 1See more

mod-inventory-update folio-org 0.1.2

1 of the 1 container images this version deploys carry CVE-2026-59889.

Container imageDigestPackageFixed in
folioci/mod-inventory-update:latestba84812b4d58
jackson-databind@2.18.2
2.18.9

Open the chart page →

878
mod-invoicefolio-org0.1.351 of 1See more

mod-invoice folio-org 0.1.35

1 of the 1 container images this version deploys carry CVE-2026-59889.

Container imageDigestPackageFixed in
folioci/mod-invoice:latest45b7b13e81e1
jackson-databind@3.1.4
3.1.5

Open the chart page →

568
mod-licensesfolio-org0.1.321 of 1See more

mod-licenses folio-org 0.1.32

1 of the 1 container images this version deploys carry CVE-2026-59889.

Container imageDigestPackageFixed in
folioci/mod-licenses:latestcfd6109bf477
jackson-databind@2.18.7
2.18.9

Open the chart page →

1,760
mod-login-samlfolio-org0.1.341 of 1See more

mod-login-saml folio-org 0.1.34

1 of the 1 container images this version deploys carry CVE-2026-59889.

Container imageDigestPackageFixed in
folioci/mod-login-saml:latest5f3358ccaa0f
jackson-databind@2.21.2
2.21.5

Open the chart page →

1,088
mod-notifyfolio-org0.1.341 of 1See more

mod-notify folio-org 0.1.34

1 of the 1 container images this version deploys carry CVE-2026-59889.

Container imageDigestPackageFixed in
folioci/mod-notify:latesta8c1a90005fc
jackson-databind@3.1.4
3.1.5

Open the chart page →

271
mod-oafolio-org0.1.21 of 1See more

mod-oa folio-org 0.1.2

1 of the 1 container images this version deploys carry CVE-2026-59889.

Container imageDigestPackageFixed in
folioci/mod-oa:latestae3b069d4ba5
jackson-databind@2.18.7
2.18.9

Open the chart page →

1,733
mod-oai-pmhfolio-org0.1.341 of 1See more

mod-oai-pmh folio-org 0.1.34

1 of the 1 container images this version deploys carry CVE-2026-59889.

Container imageDigestPackageFixed in
folioci/mod-oai-pmh:latest5cd5ef063f2a
jackson-databind@2.18.2
2.18.9

Open the chart page →

962
mod-ordersfolio-org0.1.341 of 1See more

mod-orders folio-org 0.1.34

1 of the 1 container images this version deploys carry CVE-2026-59889.

Container imageDigestPackageFixed in
folioci/mod-orders:latestfc4528220fb8
jackson-databind@3.1.4
3.1.5

Open the chart page →

456
mod-orders-storagefolio-org0.1.351 of 1See more

mod-orders-storage folio-org 0.1.35

1 of the 1 container images this version deploys carry CVE-2026-59889.

Container imageDigestPackageFixed in
folioci/mod-orders-storage:latestceeaacc3bf16
jackson-databind@3.1.4
3.1.5

Open the chart page →

442
mod-organizationsfolio-org0.1.341 of 1See more

mod-organizations folio-org 0.1.34

1 of the 1 container images this version deploys carry CVE-2026-59889.

Container imageDigestPackageFixed in
folioci/mod-organizations:latest7dc9ccf3d937
jackson-databind@2.18.6
2.18.9

Open the chart page →

808
mod-organizations-storagefolio-org0.1.341 of 1See more

mod-organizations-storage folio-org 0.1.34

1 of the 1 container images this version deploys carry CVE-2026-59889.

Container imageDigestPackageFixed in
folioci/mod-organizations-storage:lateste46892405fde
jackson-databind@2.21.4
2.21.5

Open the chart page →

665
mod-password-validatorfolio-org0.1.341 of 1See more

mod-password-validator folio-org 0.1.34

1 of the 1 container images this version deploys carry CVE-2026-59889.

Container imageDigestPackageFixed in
folioci/mod-password-validator:latestb31d75f2bf7b
jackson-databind@3.1.4
3.1.5

Open the chart page →

394
mod-patronfolio-org0.1.341 of 1See more

mod-patron folio-org 0.1.34

1 of the 1 container images this version deploys carry CVE-2026-59889.

Container imageDigestPackageFixed in
folioci/mod-patron:latest5f213acfe2f8
jackson-databind@2.18.2
2.18.9

Open the chart page →

827
mod-permissionsfolio-org0.1.351 of 1See more

mod-permissions folio-org 0.1.35

1 of the 1 container images this version deploys carry CVE-2026-59889.

Container imageDigestPackageFixed in
folioci/mod-permissions:latest5363e98c6299
jackson-databind@2.18.6
2.18.9

Open the chart page →

1,214
mod-pubsubfolio-org0.1.341 of 1See more

mod-pubsub folio-org 0.1.34

1 of the 1 container images this version deploys carry CVE-2026-59889.

Container imageDigestPackageFixed in
folioci/mod-pubsub:latest0a4fa4ad5d72
jackson-databind@2.18.6
2.18.9

Open the chart page →

1,009
mod-remote-storagefolio-org0.1.321 of 1See more

mod-remote-storage folio-org 0.1.32

1 of the 1 container images this version deploys carry CVE-2026-59889.

Container imageDigestPackageFixed in
folioci/mod-remote-storage:latest4f12177123dc
jackson-databind@2.21.4
2.21.5

Open the chart page →

571
mod-rtacfolio-org0.1.341 of 1See more

mod-rtac folio-org 0.1.34

1 of the 1 container images this version deploys carry CVE-2026-59889.

Container imageDigestPackageFixed in
folioci/mod-rtac:latestc959b2d6142f
jackson-databind@2.18.2
2.18.9

Open the chart page →

665
mod-senderfolio-org0.1.341 of 1See more

mod-sender folio-org 0.1.34

1 of the 1 container images this version deploys carry CVE-2026-59889.

Container imageDigestPackageFixed in
folioci/mod-sender:latestd88a675dddf0
jackson-databind@2.18.2
2.18.9

Open the chart page →

818
mod-serials-managementfolio-org0.1.11 of 1See more

mod-serials-management folio-org 0.1.1

1 of the 1 container images this version deploys carry CVE-2026-59889.

Container imageDigestPackageFixed in
folioci/mod-serials-management:latest571fa1ffe8c9
jackson-databind@2.18.7
2.18.9

Open the chart page →

1,733

Container images carrying it

224 by charts deploying them

A fixed version is listed for 1 of the 1 affected package.

Container imageDigestPackageFixed inUsed by
jenkins/jenkins:2.568.3-jdk21:2.568.3-lts-jdk21:ltsc1e4c349365f
jackson-databind@3.1.3
3.1.5
13
public.ecr.aws/aktosecurity/confluentinc-cp-kafka:8.2.2:8.2.2-1-ubi98e01c0305844
jackson-databind@2.21.2
2.21.5
7
apache/fineract:1.12.1a83cf1980609
jackson-databind@2.18.3
2.18.9
2
apache/kafka:4.3.177e3df905404
jackson-databind@2.21.2
2.21.5
2
apacherocketmq/rocketmq-dashboard:2.1.0ce78506bd6fe
jackson-databind@2.18.3
2.18.9
2
gisaia/arlas-permissions-server:28.0.0e612fc722e02
jackson-databind@2.21.0
2.21.5
2
gisaia/arlas-persistence-server:28.0.0f667e0ee79be
jackson-databind@2.21.0
2.21.5
2
gisaia/arlas-server:28.0.04e693e7b6f37
jackson-databind@2.21.0
2.21.5
2
gotson/komga:1.26.36c2a967bbe9a
jackson-databind@2.21.4
2.21.5
2
graviteeio/apim-gateway:4.12.19-debian05fd67a93056
jackson-databind@2.18.1
2.18.9
2
graviteeio/apim-management-api:4.12.19-debian27374522cd04
jackson-databind@3.1.1
3.1.5
2
jenkins/jenkins:2.541.3-jdk21c4098086090c
jackson-databind@2.18.0
2.18.9
2
metabase/metabase:v0.61.1.x9491ed11c901
jackson-databind@2.21.2
2.21.5
2
nacos/nacos-server:latest1c191c30c8cd
jackson-databind@2.21.2
2.21.5
2
opensearchproject/opensearch:2.18.07f6fa1efee8f
jackson-databind@2.18.0
2.18.9
2
ghcr.io/flyteorg/flyte-connectors:py3.12-v2.3.6896fc7b18b1b
jackson-databind@2.21.2
2.21.5
2
ghcr.io/kafbat/kafka-ui:v1.5.07cda86a33344
jackson-databind@2.21.2
2.21.5
2
ghcr.io/openunison/openunison-kubernetes-operator:1.0.11f4feb3323a29
jackson-databind@2.21.3
2.21.5
2
quay.io/strimzi/drain-cleaner:1.6.15fb28e9f30d0
jackson-databind@2.21.2
2.21.5
2
quay.io/strimzi/operator:0.46.0ac434a48ac2b
jackson-databind@2.18.3
2.18.9
2
acryldata/datahub-frontend-react:v1.7.0.199513cc1c45e
jackson-databind@2.21.2
2.21.5
1
acryldata/datahub-upgrade:v1.7.0.1c3db54d8fb94
jackson-databind@2.21.2
2.21.5
1
adeptiainc/adeptia-connect-migration:4.8.1f1087da3da0b
jackson-databind@2.21.1
2.21.5
1
ahmetfurkandemir/iceberg-rest-fixture-postgresql:1.10.0142231a0b8b7
jackson-databind@2.18.4
2.18.9
1
alfio/alf.io:2.0-M5-26060c836a081446
jackson-databind@2.21.2
2.21.5
1
alfresco/alfresco-activemq:5.18.7-jre17-rockylinux85472f88d9b0b
jackson-databind@2.18.2
2.18.9
1
apache/gravitino-iceberg-rest:1.3.080136ae753ee
jackson-databind@2.21.3
2.21.5
1
apache/hertzbeat:1.8.075d48a62748f
jackson-databind@2.18.2
2.18.9
1
apache/hertzbeat-collector:1.8.0a2bab1be574c
jackson-databind@2.18.2
2.18.9
1
apache/polaris:lateste66366e783f1
jackson-databind@3.2.0
3.2.1
1
apache/tika:3.3.1.090b7fa1dc018
jackson-databind@2.21.3
2.21.5
1
atlassian/bitbucket:10.2.705933f2b1cfd
jackson-databind@2.18.2
2.18.9
1
berkeleyskypilot/skypilot:0.13.03bc8bf8f4d83
jackson-databind@2.18.6
2.18.9
1
bitnamilegacy/keycloak:26.3.3-debian-12-r0da3df0976a9f
jackson-databind@2.18.2
2.18.9
1
bitnamilegacy/opensearch:2.18.0-debian-12-r0d8440eb6b290
jackson-databind@2.18.0
2.18.9
1
bluerange/bluerange:26.1.307c8f73b55df
jackson-databind@2.18.3
2.18.9
1
castlemock/castlemock:latestb7f3f1527ba9
jackson-databind@2.18.3
2.18.9
1
ckan/ckan-solr:2.11-solr9ef8e5d3e6be1
jackson-databind@2.18.0
2.18.9
1
confluentinc/cp-kafka:latest0ad069035863
jackson-databind@2.21.2
2.21.5
1
confluentinc/cp-schema-registry:latestf0cfd047a839
jackson-databind@2.21.2
2.21.5
1
consensys/teku:latest3a4f5761ae1c
jackson-databind@3.1.0
3.1.5
1
consensys/teku:25.4.1bf6ecd2ea716
jackson-databind@2.18.3
2.18.9
1
consensys/web3signer:latestf146a51a1ba3
jackson-databind@2.21.2
2.21.5
1
crushftp/crushftp11:latestae62db2d83b7
jackson-databind@2.21.4
2.21.5
1
crushftp/crushftp11:latest-devd9afab76df30
jackson-databind@2.21.4
2.21.5
1
dependencytrack/apiserver:4.14.21ba4f004e1ec
jackson-databind@2.21.1
2.21.5
1
dependencytrack/apiserver:latestf1da63ed610a
jackson-databind@2.22.0
2.22.1
1
eginnovations/agent:7.5.4e4dfe242fe9f
jackson-databind@2.21.1
2.21.5
1
epamedp/edp-gerrit:3.14.249e8fe9c4855
jackson-databind@2.21.1
2.21.5
1
erikvl87/languagetool:6.7-dockerupdate-3e1ea6a975388
jackson-databind@2.18.0
2.18.9
1

syft 1.42.1 · advisories as of 14 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.